Security
Your customer data belongs to you, not to our AI
Quack is trained on your documentation and your ticket history. That data stays isolated to your tenant and is never used to train models for any other customer.
Data handling and storage
How we store your data
-
Encryption at rest
All customer data is encrypted at rest using AES-256. This includes ingested documentation, ticket archives, and trained model weights specific to your account.
-
Encryption in transit
All data in transit is encrypted using TLS 1.3. API calls from your helpdesk to Quack, and from Quack back to your helpdesk, use HTTPS with certificate pinning on production endpoints.
-
Tenant isolation
Each customer's data, including model weights, vector embeddings, and raw ticket data, lives in a logically isolated tenant environment. There is no shared data layer between accounts.
-
Data residency
All data is stored in US-East (AWS us-east-1) by default. EU data residency (eu-west-1) is available on Scale plans upon request.
What we do not do with your data
-
No cross-tenant model training
Your ticket data and documentation are never used to train, fine-tune, or improve the model for any other customer. The model trained on your data works only for your account.
-
No data sold or shared
Quack does not sell, license, or share your customer data with third parties for any purpose other than operating the service you signed up for.
-
No retention after termination
When you cancel your account, all of your data, including trained model weights, is deleted within 30 days. You can request immediate deletion at any time.
Access controls and compliance
Access controls
-
Role-based access
Quack supports Admin, Member, and Read-only roles. Admins can manage integrations and model settings. Members can view analytics and ticket results. Read-only access is available for audit users.
-
SSO (Scale plan)
Single Sign-On via SAML 2.0 is available on the Scale plan. SCIM provisioning for automated user lifecycle management is included with SSO.
-
Audit logging
Scale plan accounts include full audit logs: who changed which setting, when a new doc source was connected, when Quack's confidence threshold was adjusted. Logs are exportable via API.
Compliance status
-
SOC 2 Type II
Our SOC 2 Type II audit is in progress with an expected completion in Q4 2026. We will publish the report upon completion. A summary of controls is available on request for enterprise evaluations.
-
GDPR
Quack acts as a data processor under GDPR. We offer a Data Processing Agreement (DPA) for all customers. EU customers can request the DPA at [email protected].
-
Vulnerability reporting
We accept security disclosures at [email protected]. We target a 48-hour acknowledgment and 14-day remediation timeline for critical issues.
Need a security review before you sign up?
We are happy to walk your security team through our controls. Email us to request a security questionnaire response or a DPA.